
Claude Now Watermarks Its Text Worldwide
Nothing you are doing becomes wrong today. But you should know which of your work now carries a mark.
Founder, Automation Squad ·
The short answer
Claude's text output now carries a statistical watermark, applied worldwide, created by biasing word choice with a private key. It survives copy-paste, light editing and translation. Only a complete rewrite removes it. It is unreliable on short text, fact-dense passages and code, and no public detection tool exists yet.
What the watermark survives, and the three-bucket sort for work you've shipped
The table is the reference. The sort underneath it is the ten-minute pass that tells you whether you need to disclose anything.
List the last few things you shipped with Claude's help
Client deliverables, published posts, graded work, anything with your name on it. You are looking for the last month or so, not your whole history.
Sort each one into three buckets
A — Claude wrote it. B — Claude edited my draft. C — I wrote it, Claude only advised. The watermark cannot tell A from B, which is exactly why you need to know which is which.
Check what your contracts, employer policy or course rules actually say
Look for a disclosure clause on AI use. Bucket A triggers most of them. Bucket C almost never does. Bucket B is the argument you want evidence for.
Keep the version history on anything in bucket B
A drafting trail is the only thing that separates 'edited with AI' from 'generated by AI' once a detector says the text is marked. Google Docs history, git, or dated drafts all work.
Disclose now if a rule requires it, rather than after a detector does
Volunteering it costs a sentence. Being asked about it later costs the benefit of the doubt.
| Situation | Watermark |
|---|---|
| Copy and paste | Survives |
| Light editing | Survives |
| Translation produced by Claude | Survives |
| Complete rewrite, every word replaced | Removed |
| Short samples | Unreliable |
| Fact-dense passages with forced terms | Unreliable |
| Code | Generally weaker |
| Images and files | C2PA metadata, not a watermark |
| Public detection API | Promised, not shipped |
Take it with you
CLAUDE WATERMARK — what it means for work I've shipped
Source: https://automationsquad.com/news/claude-text-watermark-explained/
SURVIVES: copy-paste · light editing · translation by Claude
REMOVED BY: a complete rewrite where every word is replaced
UNRELIABLE: short samples · fact-dense passages · code
IMAGES: C2PA metadata instead (nothing inside the file changes)
DETECTION: a public API is promised but not shipped yet
SCOPE: applied globally, on models from Aug 2 2026; older models
being backfilled "over the coming months"
THE THREE-BUCKET SORT
A — Claude wrote it
B — Claude edited my draft
C — I wrote it, Claude only advised
The watermark CANNOT distinguish A from B. A detector hit is evidence of
involvement, not of authorship.
[ ] Sort my last few shipped pieces into A / B / C
[ ] Check contracts / employer policy / course rules for a disclosure clause
[ ] Bucket A: disclose if any rule requires it
[ ] Bucket B: keep the version history — it's the only proof of what I did
[ ] Bucket C: no actionAnthropic published its explainer on Claude text watermarking on August 14, 2026. The technique biases the model's word selection using a private key, leaving a statistical signature that a detector holding that key can find later.
The facts, from Anthropic's own post: watermarking applies to future Claude models, and Anthropic says it is "working to add watermarking" for models launched before August 2, 2026, rolled out over the coming months. It is applied globally, and Anthropic is explicit about why — "we don't yet have a durable way to scope it by region." It survives light editing and translation; a Claude-produced translation is watermarked because every word in it was chosen by Claude. A complete rewrite in which every word is replaced removes it. Anthropic names its own limits: the watermark is weak on short samples, weak on fact-dense passages where specific terms are forced, and generally weaker in code, which often has to be exact. A public detection API is promised but not yet shipped. Files get C2PA content credentials instead, which Anthropic notes are metadata — nothing inside the file changes.
Automation Squad's take: read the limits carefully, because they cut both ways. The watermark cannot tell the difference between Claude writing something from nothing and Claude heavily editing your draft — so a detector hit is not evidence of authorship, it is evidence of involvement. That distinction is going to be lost by roughly everyone the first time a university or a client runs a check, and the burden of explaining it will land on the writer. The practical response is not to avoid Claude; it is to keep the drafting history that shows what you actually did. Anyone publishing under a byline, submitting graded work, or delivering copy under a contract that speaks to AI use should know this changed, and should know that no public detector exists yet to check their own work against.
Run this now: pick the last three pieces of writing you shipped with Claude's help and sort them into three buckets — Claude wrote it, Claude edited mine, I wrote it and Claude only advised. Then check whether any client contract, employer policy, or course rule you are bound by has a disclosure clause that the first bucket triggers. If it does, disclose it now rather than after a detector does it for you. Keep your version history on anything in bucket two; a drafting trail is the only thing that separates "edited with AI" from "generated by AI" once the detection API ships.
By the numbers
The data behind the story — figures from cited sources, with our own analysis labelled.
| Copy and paste | Survives |
| Light editing | Survives |
| Translation by Claude | Survives |
| Complete rewrite, every word replaced | Removed |
| Short samples | Unreliable |
| Fact-dense passages with forced terms | Unreliable |
| Code | Generally weaker |
| Images and files | C2PA metadata, not a watermark |
| Public detection API | Promised, not shipped |
Anthropic publishes these limits itself. The short-text and code weaknesses matter as much as the survival claims.
Questions people are asking
- Does the Claude watermark survive copy and paste?
- Yes. It survives copy-paste, light editing, and translation — a Claude-produced translation is watermarked because every word in it was chosen by Claude. Only a complete rewrite in which every word is replaced removes it.
- Can I check whether my own text is watermarked?
- Not yet. Anthropic says it will offer a watermark detection API and is working out the implementation, but nothing public has shipped. Until it does, you cannot verify your own work either way.
- Does the watermark prove Claude wrote something?
- No, and this is the distinction most likely to be lost. Anthropic states the watermark cannot distinguish between Claude writing original content and Claude heavily editing existing text. A detection hit is evidence of involvement, not of authorship — which is why keeping your drafting history matters.
- Does watermarking apply outside the EU?
- Yes. Anthropic applies it globally at launch, and is explicit about why: it does not yet have a durable way to scope watermarking by region.
- Is code watermarked too?
- Less reliably. Anthropic notes that code, which in many cases has to be exact, generally carries less watermarking than other forms of text — the technique works by biasing word choice, and code leaves far less room for that.
Sources
Further reading
- Anthropic — How Claude's text watermarking works — Read the limitations section specifically — it is the part that decides how much a future detector result is worth.
Last checked August 15, 2026 against the primary sources above, by Automation Squad Research. Spot an error? [email protected].
